6.10.10 Ensure Unused DHCP Service is Not Set

Information

The DHCP Server should be disabled when not required.

Rationale:

When hardening any computer system for security, it is important to disable or uninstall any application that is not required. The same rule applies to routers and other network devices.

JUNOS devices are able to operate as a Dynamic Host Configuration Protocol (DHCP) server, providing IP Address and other information to client systems on connected networks. DHCP Services are configured either under the [edit system services dhcp] (using the Legacy DHCPD process) or [edit system services dhcp-local-server] (using the newer Extended JDHCPD process) hierarchies.

In most larger environments, DHCP services will be provided by separate DHCP Servers rather than JUNOS Routers, Switches or Firewalls - although these may still be used in smaller networks or Branch Offices. On some JUNOS platforms the DHCP Service is configured by default, but it is recommended that it is disabled if it is not required.

Impact:

Ensure that DHCP Services are not required before disabling them.

Solution

To disable DHCP services which are not required, issue the one of the following command from the [edit system services] configuration hierarchy:
For DHCP configured with the Legacy DHCPD process:

[edit system services]
user@host#delete dhcp

Or, for DHCP configured with the Enhanced JDHCPD process:

[edit system services]
user@host#delete dhcp-local-server

Default Value:

Varies by platform. Some Branch/SME focused devices ship with DHCP services configured by default, while most Service Provider or Larger Enterprise devices have DHCP disabled by default.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Juniper

Control ID: 99440008dbd6f68d5a79a7854b521bb9f411af29b770a7b8b6e78d7d828050d1